XSS vulnerability in CMS context-menu and the repository StatusServlet 

Issue date: 04-04-2022
Affects versions: 14.7, 13.4

Security Issue ID

SECURITY-270

 

Affected Product Version(s)
14.7.3, 13.4.14 and previous releases


Severity 

normal


Description

The Wicket code that renders the javascript for displaying a context-menu in the Content Perspective allowed a logged-in user to execute javascript, because it did not escape request-parameters correctly.

Another issue was found with the Repository Status servlet which did not properly escape the message and stacktrace of an exception.

Instructions

Customers are recommended to upgrade to the latest version. As of the time of writing, 14.7.5 or 13.4.16.